URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 13 d ago. Click Reanalyze to run a fresh scan.
SUSPICIOUS · LOW CONFIDENCE

Suspicious — review required

brand Ledger scan id 49f32512 duration 8.82s signals 5 failing / 17
Risk score 0.47
47 / 100 · Medium risk
Tags
https :// newconnect-ldgr-live . framer . media /en-us
flagged registered domain path protocol / query
URL hxxps://newconnect-ldgr-live[.]framer[.]media/en-us
Host newconnect-ldgr-live[.]framer[.]media
Registered domain framer[.]media
Brand Ledger
Screenshot https://cdn.zerophish.ai/25c62787-513a-4b73-97dd-8cb2a9825ac5.jpg
Scan ID 49f32512-8102-4334-8e93-2ea36548a1e3
×
Brand typo-squat detected
ldgr ↔ ledger · Levenshtein 2 · brand: Ledger
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
!
Visual similarity to known brand
55% partial similarity to Ledger
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 17 ·
Captured page
screenshot · captured at scan live page render
L
Ledger
ledger.com
55%
Host newconnect-ldgr-live.framer.media
Registered domain framer.media
Scheme https
Content length 115345 B
HTTP 200 · text/html
JARM 7939b39b37937930320320320320128c19258acd09ccdea8faad630541ff7e
Redirect hops 1
Initial scan heuristic + LLM

The page claims to be an “Official Ledger Live” login guide, but it does not present an actual login/credential form in the provided HTML—it’s primarily informational text about using the Ledger Live app. The main suspicious signal is the hosting domain: newconnect-ldgr-live.framer.media, which is not a Ledger-registered domain, and the presence of a generic Framer footer. While the content is consistent with Ledger best practices (e.g., “never share your recovery phrase”), the mismatch between branding and domain ownership prevents a definitive legitimacy judgment.

No urgency, account-compromise warnings, or password/seed harvesting form is visible. Because evidence is limited to a short simplified HTML without assets (e.g., favicon) or redirects, confidence is conservatively set to low.

🤖 Agent run #1 autonomous investigation

Brand-impersonation page hosted on Framer’s free platform (newconnect-ldgr-live.framer.media) using Ledger branding and “Ledger Live Login” keyword targeting. No credential form detected — page is purely informational with a link to the official ledger.com. No credential harvesting possible on this page alone, but the domain impersonation and SEO bait pattern are suspicious.